Data leakage & model-side risks
P59.llm-threats.02 · Audience: guest, it-ml, language-pro · Prerequisites: Prompt injection & untrusted content
Everything you put in a prompt leaves your process — it reaches a provider, may be retained, and can resurface. Everything you log stays with you, often for years. Both paths leak the same things: emails, tokens, keys, customer data.
This module builds the redactor that guards both, then steps back to the systemic risks: system-prompt exfiltration (treat it as not secret), output filtering, and tenant isolation — which is really P56 authorization applied to a vector store.
Ask the mentor about this module
Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.
Keeping your files on this device
Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.
Rung 1 — redact secrets and PII before they travel
Loading exercise…
Interview rung — data leakage & tenant isolation (free-form)
Loading exercise…
My notes on this module
Loading your notes...
Where next?
This module unlocks